Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 312 573

Количество 312 573

github логотип

GHSA-2ph8-rh6h-6gpc

больше 3 лет назад

CA Automic Automation 12.2 and 12.3 contain an insecure memory handling vulnerability in the Automic agent that could allow a remote attacker to potentially access sensitive data.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2ph6-gc2m-75x2

почти 4 года назад

Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.

EPSS: Низкий
github логотип

GHSA-2ph5-q865-h92c

больше 3 лет назад

License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License Manager Service runs via unspecified vectors.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2ph5-82ch-xwq8

больше 3 лет назад

A vulnerability in the URL block page of Cisco Umbrella could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user in a network protected by Umbrella. The vulnerability is due to insufficient validation of input parameters passed to that page. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information. This vulnerability has been fixed in the current version of Cisco Umbrella. Cisco Umbrella is a cloud service.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2ph4-qcc6-cw8c

больше 3 лет назад

The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2ph2-r6cr-hgrj

больше 3 лет назад

Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.

EPSS: Высокий
github логотип

GHSA-2ph2-8m3c-5288

больше 3 лет назад

The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

EPSS: Низкий
github логотип

GHSA-2pgw-6775-r4r8

больше 3 лет назад

The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-2pgv-ghf3-xj9q

больше 3 лет назад

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-2pgv-8585-494w

7 месяцев назад

Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2pgq-w6mw-xjv4

почти 3 года назад

Information disclosure due to buffer overread in Linux sensors

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-2pgq-v89h-j58m

около 1 года назад

Cross-Site Request Forgery (CSRF) vulnerability in Sam Hoe SH Slideshow allows Stored XSS.This issue affects SH Slideshow: from n/a through 4.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-2pgp-h9fc-5pw2

около 1 месяца назад

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

EPSS: Низкий
github логотип

GHSA-2pgp-5w4w-9255

больше 2 лет назад

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-2pgm-5x83-qh65

больше 3 лет назад

RuoYi v3.8.3 has a Weak password vulnerability in the management system.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2pgj-cx4m-4rf6

около 3 лет назад

Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2pgj-5cv2-6xxw

4 месяца назад

FuelVM is vulnerable to heap memory allocation re-use bug

EPSS: Низкий
github логотип

GHSA-2pgh-p3w2-v9wc

почти 4 года назад

PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.

EPSS: Средний
github логотип

GHSA-2pgg-h82p-8cpr

около 2 лет назад

Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-2pgf-m766-9x3m

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-2ph8-rh6h-6gpc

CA Automic Automation 12.2 and 12.3 contain an insecure memory handling vulnerability in the Automic agent that could allow a remote attacker to potentially access sensitive data.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2ph6-gc2m-75x2

Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.

2%
Низкий
почти 4 года назад
github логотип
GHSA-2ph5-q865-h92c

License Manager Service of YOKOGAWA products (CENTUM VP (R5.01.00 - R6.06.00), CENTUM VP Entry Class (R5.01.00 - R6.06.00), ProSafe-RS (R3.01.00 - R4.04.00), PRM (R4.01.00 - R4.02.00), B/M9000 VP(R7.01.01 - R8.02.03)) allows remote attackers to bypass access restriction to send malicious files to the PC where License Manager Service runs via unspecified vectors.

CVSS3: 9.8
10%
Низкий
больше 3 лет назад
github логотип
GHSA-2ph5-82ch-xwq8

A vulnerability in the URL block page of Cisco Umbrella could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user in a network protected by Umbrella. The vulnerability is due to insufficient validation of input parameters passed to that page. An attacker could exploit this vulnerability by persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information. This vulnerability has been fixed in the current version of Cisco Umbrella. Cisco Umbrella is a cloud service.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2ph4-qcc6-cw8c

The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2ph2-r6cr-hgrj

Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.

86%
Высокий
больше 3 лет назад
github логотип
GHSA-2ph2-8m3c-5288

The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-2pgw-6775-r4r8

The BMI BMR Calculator WordPress plugin through 1.3 does not sanitise and escape arbitrary POST data before outputting it back in the response, leading to a Reflected Cross-Site Scripting

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pgv-ghf3-xj9q

LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution

CVSS3: 9.8
15%
Средний
больше 3 лет назад
github логотип
GHSA-2pgv-8585-494w

Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions.

CVSS3: 8.8
7%
Низкий
7 месяцев назад
github логотип
GHSA-2pgq-w6mw-xjv4

Information disclosure due to buffer overread in Linux sensors

CVSS3: 5.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-2pgq-v89h-j58m

Cross-Site Request Forgery (CSRF) vulnerability in Sam Hoe SH Slideshow allows Stored XSS.This issue affects SH Slideshow: from n/a through 4.3.

CVSS3: 7.1
0%
Низкий
около 1 года назад
github логотип
GHSA-2pgp-h9fc-5pw2

Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.

около 1 месяца назад
github логотип
GHSA-2pgp-5w4w-9255

Govee Home app has unprotected access to WebView component which can be opened by any app on the device. By sending an URL to a specially crafted site, the attacker can execute JavaScript in context of WebView or steal sensitive user data by displaying phishing content.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2pgm-5x83-qh65

RuoYi v3.8.3 has a Weak password vulnerability in the management system.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-2pgj-cx4m-4rf6

Insufficient policy enforcement in Autofill in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-2pgj-5cv2-6xxw

FuelVM is vulnerable to heap memory allocation re-use bug

4 месяца назад
github логотип
GHSA-2pgh-p3w2-v9wc

PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.

18%
Средний
почти 4 года назад
github логотип
GHSA-2pgg-h82p-8cpr

Mattermost fails to validate if a relative path is passed in /plugins/playbooks/api/v0/telemetry/run/<telem_run_id> as a telemetry run ID, allowing an attacker to use a path traversal payload that points to a different endpoint leading to a CSRF attack.

CVSS3: 7.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-2pgf-m766-9x3m

Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 7.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу